CVE-2026-7734

MEDIUM

osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service

Title source: cna
STIX 2.1

Description

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. Such manipulation of the argument data leads to denial of service. The attack may be performed from remote. Upgrading to version 4.4.0 will fix this issue. The name of the patch is f9f7b55ec258e514be0264871fa645a2c3edad11. You should upgrade the affected component.

References (6)

Core 6
Core References
Vdb Entry, Technical Description vdb-entry technical-description
VDB-360909 | osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of service
https://vuldb.com/vuln/360909
Signature, Permissions Required signature permissions-required
VDB-360909 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/360909/cti
Third Party Advisory third-party-advisory
Submit #807581 | GoBGP 4.3.0 Infinite Loop
https://vuldb.com/submit/807581

Scores

CVSS v3 5.3
EPSS 0.0006
EPSS Percentile 17.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-404
Status published
Products (5)
osrg/GoBGP 4.0
osrg/GoBGP 4.1
osrg/GoBGP 4.2
osrg/GoBGP 4.3.0
osrg/GoBGP 4.4.0
Published May 04, 2026
Tracked Since May 04, 2026